On this page
Atomicorp WAF Rule 377360
Rule Summary
- Rule ID: 377360
- Status: Active
- Alert message: Atomicorp.com WAF Rules - Login Failure Detection: Wordpress Login Attempt Failure
- Observed CWEs: CWE-20 (1), CWE-22 (8), CWE-23 (1), CWE-79 (79), CWE-80 (1), CWE-89 (4), CWE-94 (3), CWE-98 (1), CWE-178 (1), CWE-200 (2), CWE-269 (2), CWE-284 (1), CWE-287 (2), CWE-306 (1), CWE-352 (6), CWE-425 (1), CWE-434 (5), CWE-601 (4), CWE-611 (1), CWE-639 (1), CWE-640 (1), CWE-862 (7), CWE-863 (2), CWE-918 (2)
- Revision: 2
- Rule severity: Warning (4)
- Phase: 5 (logging)
- Rule action: pass
- Public tags: no_ar
- Logging: auditlog
Description
This rule detects behavior identified by its current alert as “Login Failure Detection: Wordpress Login Attempt Failure”. It evaluates during the logging phase and records the match without a disruptive action.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2023-6825 | WordPress File Manager <= 7.2.1 - Directory Traversal | file manager | 9.9 (v3.1) | Critical |
| CVE-2017-18580 | WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution | shortcodes ultimate | 9.8 (v3.0) | Critical |
| CVE-2020-10257 | ThemeREX Addons - Remote Code Execution | themerex | 9.8 (v3.1) | Critical |
| CVE-2021-24215 | Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation | controlled admin access | 9.8 (v3.1) | Critical |
| CVE-2021-34621 | WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness | profilepress | 9.8 (v3.1) | Critical |
| CVE-2022-0479 | Popup Builder Plugin - SQL Injection and Cross-Site Scripting | popup builder | 9.8 (v3.1) | Critical |
| CVE-2023-30869 | Easy Digital Downloads - Privilege Escalation | easy digital downloads | 9.8 (v3.1) | Critical |
| CVE-2025-11833 | Post SMTP <= 3.6.0 - Email Log Disclosure | post smtp mailer | 9.8 (v3.1) | Critical |
| CVE-2025-13486 | Advanced Custom Fields Extended < 0.9.2 - Remote Code Execution | Advanced Custom Fields: Extended | 9.8 (v3.1) | Critical |
| CVE-2025-14998 | Branda WordPress plugin - Privilege Escalation | Branda – White Label & Branding, Free Login Page Customizer | 9.8 (v3.1) | Critical |
| CVE-2025-1562 | Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control | funnelkit automations | 9.8 (v3.1) | Critical |
| CVE-2026-11387 | SMS Alert – SMS & OTP for WooCommerce - Privilege Escalation | sms-alert | 9.8 (v3.1) | Critical |
| CVE-2026-19598 | Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router | pods | 9.8 (v3.1) | Critical |
| CVE-2024-8673 | Z-Downloads < 1.11.7 - Cross-Site Scripting | z-downloads | 9.1 (v3.1) | Critical |
| CVE-2025-49029 | WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution | Custom Login And Signup Widget | 9.1 (v3.1) | Critical |
| CVE-2020-9043 | WordPress wpCentral <1.5.1 - Information Disclosure | wpcentral | 8.8 (v3.1) | High |
| CVE-2021-24347 | WordPress SP Project & Document Manager <4.22 - Authenticated Shell Upload | sp project & document manager | 8.8 (v3.1) | High |
| CVE-2021-25082 | WordPress Popup Builder < 4.0.7 - Remote Code Execution | popup builder | 8.8 (v3.1) | High |
| CVE-2022-0439 | Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection | email subscribers & newsletters | 8.8 (v3.1) | High |
| CVE-2022-1329 | Elementor Website Builder - Remote Code Execution | website builder | 8.8 (v3.1) | High |
| CVE-2023-23897 | Ozette Plugins - Cross-Site Request Forgery | simple mobile url redirect | 8.8 (v3.1) | High |
| CVE-2023-48777 | WordPress Elementor 3.18.1 - File Upload/Remote Code Execution | website builder | 8.8 (v3.1) | High |
| CVE-2024-30464 | WPZOOM Social Icons Widget <= 4.2.15 - Missing Authorization | social-icons-widget-by-wpzoom | 8.8 (v3.1) | High |
| CVE-2025-2075 | Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | uncanny automator | 8.8 (v3.1) | High |
| CVE-2025-32614 | EventON Lite <= 2.4 - Authenticated Local File Inclusion | flavor | 8.8 (v3.1) | High |
| CVE-2026-7467 | Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalation | expand-maker | 8.8 (v3.1) | High |
| CVE-2026-34885 | WordPress Media Library Assistant <= 3.34 - SQL Injection | Media LIbrary Assistant | 8.5 (v3.1) | High |
| CVE-2012-10018 | WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload | mapplic | 8.3 (v3.1) | High |
| CVE-2020-36836 | WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion | wp fastest cache | 8.0 (v3.1) | High |
| CVE-2019-14206 | Nevma Adaptive Images - Arbitrary File Deletion | adaptive images | 7.5 (v3.1) | High |
| CVE-2021-24170 | User Profile Picture < 2.5.0 - Sensitive Information Disclosure | user profile picture | 7.5 (v3.1) | High |
| CVE-2021-24644 | Images to WebP < 1.9 - Authenticated Local File Inclusion | images to webp | 7.5 (v3.1) | High |
| CVE-2024-45293 | TablePress < 2.4.3 - XXE Injection | tablepress | 7.5 (v3.1) | High |
| CVE-2021-24155 | WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload | backup guard | 7.2 (v3.1) | High |
| CVE-2021-24970 | WordPress All-In-One Video Gallery <2.5.0 - Local File Inclusion | all-in-one video gallery | 7.2 (v3.1) | High |
| CVE-2023-0900 | AP Pricing Tables Lite <= 1.1.6 - SQL Injection | pricing table builder | 7.2 (v3.1) | High |
| CVE-2023-47873 | WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload | wp child theme generator | 7.2 (v3.1) | High |
| CVE-2025-5961 | WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload | migration, backup, staging | 7.2 (v3.1) | High |
| CVE-2024-10152 | Simple Certain Time to Show Content - Cross-Site Scripting | simple certain time to show content | 7.1 (v3.1) | High |
| CVE-2024-12638 | Bulk Me Now! Plugin <= 2.0 - Cross-Site Scripting | bulk me now! | 7.1 (v3.1) | High |
| CVE-2024-12749 | WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting | competition form | 7.1 (v3.1) | High |
| CVE-2024-12878 | Lazy Blocks <= 3.8.2 - Cross-Site Scripting | lazy blocks | 7.1 (v3.1) | High |
| CVE-2024-13055 | Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting | dyn business panel | 7.1 (v3.1) | High |
| CVE-2024-13094 | WP Triggers Lite - Cross-Site Scripting | wp triggers lite | 7.1 (v3.1) | High |
| CVE-2024-13330 | JustRows WordPress - Cross-Site Scripting | justrows free | 7.1 (v3.1) | High |
| CVE-2024-13569 | WordPress Front End Users - Reflected XSS | front end users | 7.1 (v3.1) | High |
| CVE-2024-13624 | WordPress WPMovieLibrary Plugin <= 2.1.4.8 - Cross-Site Scripting | wpmovielibrary | 7.1 (v3.1) | High |
| CVE-2015-2755 | WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting | ab google map travel | 6.8 (v2.0) | Medium |
| CVE-2020-8615 | Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery | tutor lms | 6.5 (v3.1) | Medium |
| CVE-2022-1398 | External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgery | external media without import | 6.5 (v3.1) | Medium |
| CVE-2023-3345 | LMS by Masteriyo < 1.6.8 - Information Exposure | masteriyo | 6.5 (v3.1) | Medium |
| CVE-2024-9765 | EKC Tournament Manager WordPress plugin - Path Traversal | ekc tournament manager | 6.5 (v3.1) | Medium |
| CVE-2025-13652 | WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection | CBX Bookmark & Favorite | 6.5 (v3.1) | Medium |
| CVE-2025-13418 | Responsive Pricing Table <= 5.1.12 - Cross-Site Scripting | Responsive Pricing Table | 6.4 (v3.1) | Medium |
| CVE-2015-8350 | WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS | call to action | 6.1 (v3.0) | Medium |
| CVE-2017-18590 | Timesheet Plugin < 0.1.5 - Cross-Site Scripting | timesheet | 6.1 (v3.0) | Medium |
| CVE-2020-36731 | Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update | flexible checkout fields for woocommerce | 6.1 (v3.1) | Medium |
| CVE-2021-24165 | WordPress Ninja Forms <3.4.34 - Open Redirect | ninja forms | 6.1 (v3.1) | Medium |
| CVE-2021-24213 | GiveWP <= 2.9.7 - Cross-Site Scripting | givewp | 6.1 (v3.1) | Medium |
| CVE-2021-24286 | WordPress Plugin Redirect 404 to Parent 1.3.0 - Cross-Site Scripting | redirect 404 to parent | 6.1 (v3.1) | Medium |
| CVE-2021-24287 | WordPress Select All Categories and Taxonomies <1.3.2 - Cross-Site Scripting | select all categories and taxonomies, change checkbox to radio buttons | 6.1 (v3.1) | Medium |
| CVE-2021-24452 | WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting | w3 total cache | 6.1 (v3.1) | Medium |
| CVE-2021-24657 | Limit Login Attempts WordPress - Stored Cross-site Scripting | limit login attempts | 6.1 (v3.1) | Medium |
| CVE-2021-24876 | Registrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site Scripting | registrations for the events calendar | 6.1 (v3.1) | Medium |
| CVE-2022-0189 | WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting | wp rss aggregator | 6.1 (v3.1) | Medium |
| CVE-2023-0514 | Membership Database <= 1.0 - Cross-Site Scripting | membership database | 6.1 (v3.1) | Medium |
| CVE-2023-2272 | Tiempo.com <= 0.1.2 - Cross-Site Scripting | tiempo | 6.1 (v3.1) | Medium |
| CVE-2023-2518 | WordPress Easy Forms for Mailchimp Plugin < 6.8.9 - Cross-Site Scripting | easy forms for mailchimp | 6.1 (v3.1) | Medium |
| CVE-2023-37979 | Ninja Forms < 3.6.26 - Cross-Site Scripting | ninja forms | 6.1 (v3.1) | Medium |
| CVE-2023-4151 | Store Locator WordPress < 1.4.13 - Cross-Site Scripting | store locator | 6.1 (v3.1) | Medium |
| CVE-2023-4284 | WordPress Post Timeline Plugin < 2.2.6 - Cross-Site Scripting | post timeline | 6.1 (v3.1) | Medium |
| CVE-2024-12732 | AffiliateImporterEb <= 1.0.6 - Reflected XSS | affiliateimportereb | 6.1 (v3.1) | Medium |
| CVE-2024-12734 | Advance Post Prefix WordPress plugin - Reflected XSS | advance post prefix | 6.1 (v3.1) | Medium |
| CVE-2024-12737 | WP BASE Booking - Reflected XSS | wp base booking of appointments, services and events | 6.1 (v3.1) | Medium |
| CVE-2024-12873 | Custom Field Manager WordPress - Cross-Site Scripting | custom field manager | 6.1 (v3.1) | Medium |
| CVE-2024-13112 | WP MediaTagger <= 4.1.1 - Cross-Site Scripting | wp mediatagger | 6.1 (v3.1) | Medium |
| CVE-2024-13114 | WP Projects Portfolio <= 3.0 - Cross-Site Scripting | wp projects portfolio with client testimonials | 6.1 (v3.1) | Medium |
| CVE-2024-13219 | Privacy Policy Genius - Cross-Site Scripting | privacy policy genius | 6.1 (v3.1) | Medium |
| CVE-2024-13220 | WordPress Google Map Professional - Cross-Site Scripting | google map professional | 6.1 (v3.1) | Medium |
| CVE-2024-13221 | Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting | fantastic elasticsearch | 6.1 (v3.1) | Medium |
| CVE-2024-13224 | SlideDeck 1 Lite Content Slider - Cross-Site Scripting | slidedeck 1 lite content slider | 6.1 (v3.1) | Medium |
| CVE-2024-13225 | ECT Home Page Products - Reflected XSS | ect home page products | 6.1 (v3.1) | Medium |
| CVE-2024-13226 | A5 Custom Login Page - Reflected XSS | a5 custom login page | 6.1 (v3.1) | Medium |
| CVE-2024-13325 | Glossy WordPress - Reflected XSS | glossy | 6.1 (v3.1) | Medium |
| CVE-2024-13326 | iBuildApp <= 0.2.0 - Reflected Cross-Site Scripting | ibuildapp | 6.1 (v3.1) | Medium |
| CVE-2024-13327 | Musicbox WordPress - Reflected XSS | musicbox | 6.1 (v3.1) | Medium |
| CVE-2024-13331 | WP Dream Carousel < 1.0.1b - Cross-Site Scripting | wp dream carousel | 6.1 (v3.1) | Medium |
| CVE-2024-13492 | Guten Free Options - Cross Site Scripting | guten free options | 6.1 (v3.1) | Medium |
| CVE-2024-13543 | Zarinpal Paid Download - Reflected XSS | zarinpal paid download | 6.1 (v3.1) | Medium |
| CVE-2024-13570 | WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scripting | stray random quotes | 6.1 (v3.1) | Medium |
| CVE-2024-13619 | LifterLMS < 8.0.1 - Cross-Site Scripting | lifterlms | 6.1 (v3.1) | Medium |
| CVE-2024-13628 | WP Pricing Table - Reflected XSS | wp pricing table | 6.1 (v3.1) | Medium |
| CVE-2024-13630 | NewsTicker <= 1.0 - Reflected Cross-Site Scripting | newsticker | 6.1 (v3.1) | Medium |
| CVE-2024-13634 | Post Sync Plugin <= 1.1 - Cross-Site Scripting | post sync | 6.1 (v3.1) | Medium |
| CVE-2024-29138 | WordPress Restrict User Access <= 2.5 - Cross-Site Scripting | restrict user access | 6.1 (v3.1) | Medium |
| CVE-2024-29792 | Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting | unlimited elements for elementor | 6.1 (v3.1) | Medium |
| CVE-2024-29931 | WP Go Maps <= 9.0.29 - Cross-Site Scripting | wp go maps | 6.1 (v3.1) | Medium |
| CVE-2024-30194 | Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting | sunshine photo cart | 6.1 (v3.1) | Medium |
| CVE-2024-3032 | WordPress Themify Builder < 7.5.8 - Open Redirect | builder | 6.1 (v3.1) | Medium |
| CVE-2024-37261 | WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting | wp-lister lite for amazon | 6.1 (v3.1) | Medium |
| CVE-2024-39646 | WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS | custom 404 pro | 6.1 (v3.1) | Medium |
| CVE-2024-43971 | Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting | sunshine photo cart | 6.1 (v3.1) | Medium |
| CVE-2024-4439 | WordPress Core <6.5.2 - Cross-Site Scripting | WordPress | 6.1 (v3.1) | Medium |
| CVE-2024-4455 | YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting | yith woocommerce ajax search | 6.1 (v3.1) | Medium |
| CVE-2024-47374 | LiteSpeed Cache <= 6.5.0.2 - Stored XSS | litespeed cache | 6.1 (v3.1) | Medium |
| CVE-2024-6651 | WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting | wp-file-upload | 6.1 (v3.1) | Medium |
| CVE-2024-6753 | Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting | social auto poster | 6.1 (v3.1) | Medium |
| CVE-2024-7354 | Ninja Forms 3.8.6-3.8.10 - Cross-Site Scripting | ninja forms | 6.1 (v3.1) | Medium |
| CVE-2025-4652 | Broadstreet WordPress plugin - Reflected XSS | broadstreet | 6.1 (v3.1) | Medium |
| CVE-2026-1296 | Frontend Post Submission Manager Lite <= 1.2.7 - Open Redirect | Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin | 6.1 (v3.1) | Medium |
| CVE-2017-8295 | WordPress Core < 4.7.4 - Unauthorized Password Reset | WordPress | 5.9 (v3.0) | Medium |
| CVE-2024-3753 | Hostel < 1.1.5.3 - Cross-Site Scripting | hostel | 5.9 (v3.1) | Medium |
| CVE-2025-28906 | Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting | Skitter Slideshow | 5.9 (v3.1) | Medium |
| CVE-2017-14725 | WordPress < 4.8.2 - Authenticated Open Redirect | WordPress | 5.4 (v3.0) | Medium |
| CVE-2017-17092 | WordPress < 4.9.1 - Authenticated JavaScript File Upload | WordPress | 5.4 (v3.0) | Medium |
| CVE-2018-16363 | WordPress File Manager < 3.0 - Cross-Site Scripting | file manager | 5.4 (v3.0) | Medium |
| CVE-2021-33851 | WordPress Customize Login Image <3.5.3 - Cross-Site Scripting | customize login image | 5.4 (v3.1) | Medium |
| CVE-2021-36873 | WordPress iQ Block Country <=1.2.11 - Cross-Site Scripting | iq block country | 5.4 (v3.1) | Medium |
| CVE-2022-0765 | WordPress Loco Translate < 2.6.1 - Cross-Site Scripting | loco translate | 5.4 (v3.1) | Medium |
| CVE-2022-3506 | WordPress Related Posts <2.1.3 - Stored Cross-Site Scripting | related posts | 5.4 (v3.1) | Medium |
| CVE-2023-7246 | System Dashboard < 2.8.10 - Cross-Site Scripting | system dashboard | 5.4 (v3.1) | Medium |
| CVE-2024-10146 | Simple File List < 6.1.13 - Reflected Cross-Site Scripting | simple file list | 5.4 (v3.1) | Medium |
| CVE-2024-13097 | WP Finance Plugin <= 1.3.6 - Cross-Site Scripting | wp finance | 5.4 (v3.1) | Medium |
| CVE-2024-13098 | WordPress Email Newsletter - Reflected XSS | wordpress email newsletter | 5.4 (v3.1) | Medium |
| CVE-2024-13099 | Widget4Call WordPress - Cross-Site Scripting | widget4call | 5.4 (v3.1) | Medium |
| CVE-2024-2473 | WPS Hide Login <= 1.9.15.2 - Login Page Disclosure | wps hide login | 5.3 (v3.1) | Medium |
| CVE-2022-2863 | WordPress WPvivid Backup <0.9.76 - Local File Inclusion | migration, backup, staging | 4.9 (v3.1) | Medium |
| CVE-2024-10708 | System Dashboard < 2.8.15 - Admin+ Path Traversal | system dashboard | 4.9 (v3.1) | Medium |
| CVE-2021-24681 | Duplicate Page WordPress - Stored Cross-Site Scripting | duplicate page | 4.8 (v3.1) | Medium |
| CVE-2022-0535 | WordPress E2Pdf <1.16.45 - Cross-Site Scripting | e2pdf | 4.8 (v3.1) | Medium |
| CVE-2022-0873 | WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting | gmedia gallery | 4.8 (v3.1) | Medium |
| CVE-2022-1029 | Limit Login Attempts - Stored Cross-Site Scripting | limit login attempts | 4.8 (v3.1) | Medium |
| CVE-2022-4260 | WordPress WP-Ban <1.69.1 - Stored Cross-Site Scripting | wp-ban | 4.8 (v3.1) | Medium |
| CVE-2023-2009 | Pretty Url <= 1.5.4 - Cross-Site Scripting | pretty url | 4.8 (v3.1) | Medium |
| CVE-2023-2178 | Aajoda Testimonials < 2.2.2 - Cross-Site Scripting | aajoda testimonials | 4.8 (v3.1) | Medium |
| CVE-2023-2224 | Seo By 10Web < 1.2.7 - Cross-Site Scripting | seo | 4.8 (v3.1) | Medium |
| CVE-2022-2546 | WordPress All-in-One WP Migration <=7.62 - Cross-Site Scripting | all-in-one wp migration | 4.7 (v3.1) | Medium |
| CVE-2024-13627 | OWL Carousel Slider - Cross-Site Scripting | owl carousel slider | 4.7 (v3.1) | Medium |
| CVE-2026-0743 | WP Content Permission <= 1.2 - Cross-Site Scripting | WP Content Permission | 4.4 (v3.1) | Medium |
| CVE-2022-29495 | WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery | popup builder | 4.3 (v3.1) | Medium |
| CVE-2021-25075 | WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scripting | duplicate page or post | 3.5 (v3.1) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.